CISCO-IPSEC-FLOW-MONITOR-MIB

MIB Reference — IPNetwork Monitor · Updated September 09, 2026

All MIBsCISCO-IPSEC-FLOW-MONITOR-MIB

Organization: Tivoli Systems and Cisco Systems

Last Updated: 2007-10-24

Category: Cisco Devices, VPN and Security

Description: Monitors active IPSec tunnels, security associations, and encrypted traffic flow statistics on Cisco devices.

IPNetwork Monitor uses several OIDs from this MIB in network discovery and polling the applicable devices. Start monitoring CISCO-IPSEC-FLOW-MONITOR-MIB with a free 30-day trial of IPNetwork Monitor.

What Is CISCO-IPSEC-FLOW-MONITOR-MIB?

CISCO-IPSEC-FLOW-MONITOR-MIB is a Cisco MIB, designed to align with an IETF standard structure with Cisco-specific features excluded, for monitoring IPSec-based VPN structures on Cisco routers and security appliances. It exposes IKE (Internet Key Exchange) tunnel and phase statistics, including active and previous tunnel counts, inbound/outbound octet and packet counters, dropped packets, notify messages, and Phase 2 exchange success/invalid/reject counts. This is a performance and fault-monitoring MIB for VPN infrastructure: operators track cikeGlobalActiveTunnels to see how many IPSec tunnels are up, watch drop and invalid/reject counters to detect negotiation failures or attacks, and use octet/packet counters for VPN traffic accounting. It explicitly references IPSec/ISAKMP/IKE standards terminology and is intended to interoperate as an IETF-style MIB, though it ships as a Cisco enterprise module. It is typically deployed on Cisco VPN routers, firewalls, or concentrators terminating site-to-site or remote-access IPSec tunnels. This is a heavily searched Cisco MIB, since cisco-ipsec-flow-monitor-mib is the standard reference for monitoring IPsec tunnel/flow statistics on Cisco VPN gateways via SNMP.

IPNetwork Monitor allows you to monitor SNMP objects defined in CISCO-IPSEC-FLOW-MONITOR-MIB. Use the built-in SNMP Monitoring Browser to explore available variables, view their current values and descriptions, and select the objects you want to monitor. You can then create SNMP monitors, configure thresholds, and receive alerts when monitored values change.

Supported Devices

  • Cisco router/firewall/VPN concentrator terminating IPSec tunnels

Monitoring Examples

An operator would poll cikeGlobalActiveTunnels to track how many IKE/IPSec tunnels are currently established and compare against cikeGlobalPreviousTunnels to see churn. Rising cikeGlobalInDropPkts or cikeGlobalInP2ExchgInvalids / cikeGlobalInP2ExchgRejects indicates IKE negotiation problems or a misconfigured peer, while cikeGlobalInOctets and cikeGlobalInPkts give raw encrypted traffic volume for capacity planning. cikeGlobalInP2SaDelRequests spikes could reveal tunnels being torn down unexpectedly, useful when diagnosing VPN instability.

What Can Be Monitored

  • active/previous IKE tunnel counts
  • inbound/outbound encrypted octets and packets
  • dropped packets
  • Phase 2 exchange invalid/reject counts
  • SA deletion requests
  • IKE notify message counts
Imported Objects

From CISCO-MEDIA-GATEWAY-MIB

cmgwIndexOBJECT-TYPE

From CISCO-SMI

ciscoMgmtOBJECT-IDENTITY

From SNMPv2-CONF

MODULE-COMPLIANCE
NOTIFICATION-GROUP
OBJECT-GROUP

From SNMPv2-SMI

Counter32
Counter64
Gauge32
Integer32
MODULE-IDENTITY
NOTIFICATION-TYPE
OBJECT-TYPE
Unsigned32

From SNMPv2-TC

DisplayString
TEXTUAL-CONVENTION
TimeInterval
TimeStamp
TruthValue

How to Use in IPNetwork Monitor

Example using cikeGlobalPreviousTunnels OID:

Select a Cisco router/firewall/VPN concentrator terminating IPsec tunnel as the target host to create a monitor — the SNMP service should be up and running on it. Click New Monitor, then check SNMP Custom on the Favorites tab, click Next, and confirm the host. On the next page, click Select... to open the built-in SNMP MIB Browser and type cikeGlobalPreviousTunnels into the Find box to locate it in the OID tree, then select it and click OK. The total number of previously active IPsec Phase-1 IKE Tunnels. On the monitor's Main parameters page you can set the target's SNMP port (default 161), credentials, polling interval, and other settings — see the SNMP Monitor help for details. On the State conditions and Alerting tabs, configure when the monitor should change state and trigger an alert; since this is a Counter32-type OID, Value bounds is the most useful condition here — trigger an alert if the counter increases sharply between polls relative to its normal baseline (in SAs), since an unexpected spike often reflects a real change in traffic or activity. Click Finish to create the monitor; you can adjust any parameter later.
OIDs

RFC description

Cisco IPSec VPN flow monitoring for security association and tunnel management.

Start monitoring Cisco router/firewall/VPN concentrator terminating IPsec tunnels with a free 30-day trial of IPNetwork Monitor. Import MIBs, browse SNMP OIDs, create custom SNMP monitors, configure alerts, and monitor any SNMP-enabled network device from a single console.

Download CISCO-IPSEC-FLOW-MONITOR-MIB